Cybersecurity Hacking in HIPAA-Covered Entities: A Longitudinal Trend Analysis

preprint OA: closed CC-BY-4.0
📄 Open PDF Full text JSON View at publisher

Abstract

Abstract Background – As healthcare systems increasingly rely on interconnected digital infrastructures and third-party Business Associates (BAs), they have inadvertently expanded the cyber-attack surface. This study analyzed 6,374 large-scale data breaches (500+ records) reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024. Objective – To evaluate the evolving landscape of large-scale healthcare data breaches by analyzing the frequency, record impact, and longitudinal trends of data breach incidents, specifically comparing the vulnerabilities of healthcare providers versus third-party Business Associates (BAs). Methods – Using a multiple regression analysis, we compare an ordinary least squares (OLS) model and a generalized linear model (GLM) with a log link and gamma distribution. This study analyzed 6,374 large-scale data breaches (500+ records) reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024. We then used STATA to analyze the frequency, and a log-transformed analysis was used to smooth the data distribution and minimize skew of the data. Regression model: 𝐿𝑛(𝑏𝑟𝑒𝑎𝑐ℎ) 𝑖𝑠𝑚𝑡 =𝛽 0 +𝛽 1 𝐻𝑃+𝛽 2 𝐻𝑃𝑙𝑎𝑛+𝛽 3 𝐻𝐶𝐻+𝛼 𝑠 +𝛾 𝑚 +𝜇 𝑡 +𝜀 𝑖𝑠𝑚𝑡 Results – Notably, while healthcare providers report a higher volume of incident growth, Business Associates (BAs) exhibit a higher per-incident impact, functioning as a force multiplier for data exposure. Threat actor methodologies have shifted from opportunistic attacks on individual providers to high-leverage, systemic exploitation of centralized infrastructure. Conclusions - The rise of hacking necessitates a robust re-evaluation of supply-chain cybersecurity protocols and ethical governance to protect patient privacy and national economic stability.
Full text 37,951 characters · extracted from preprint-html · click to expand
Cybersecurity Hacking in HIPAA-Covered Entities: A Longitudinal Trend Analysis | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Cybersecurity Hacking in HIPAA-Covered Entities: A Longitudinal Trend Analysis Tiffany C. Jackman, Agnitra Roy Choudhury, Douglas A. Jones This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-9151808/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Background – As healthcare systems increasingly rely on interconnected digital infrastructures and third-party Business Associates (BAs), they have inadvertently expanded the cyber-attack surface. This study analyzed 6,374 large-scale data breaches (500+ records) reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024. Objective – To evaluate the evolving landscape of large-scale healthcare data breaches by analyzing the frequency, record impact, and longitudinal trends of data breach incidents, specifically comparing the vulnerabilities of healthcare providers versus third-party Business Associates (BAs). Methods – Using a multiple regression analysis, we compare an ordinary least squares (OLS) model and a generalized linear model (GLM) with a log link and gamma distribution. This study analyzed 6,374 large-scale data breaches (500+ records) reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024. We then used STATA to analyze the frequency, and a log-transformed analysis was used to smooth the data distribution and minimize skew of the data. Regression model: 𝐿𝑛(𝑏𝑟𝑒𝑎𝑐ℎ) 𝑖𝑠𝑚𝑡 =𝛽 0 +𝛽 1 𝐻𝑃+𝛽 2 𝐻𝑃𝑙𝑎𝑛+𝛽 3 𝐻𝐶𝐻+𝛼 𝑠 +𝛾 𝑚 +𝜇 𝑡 +𝜀 𝑖𝑠𝑚𝑡 Results – Notably, while healthcare providers report a higher volume of incident growth, Business Associates (BAs) exhibit a higher per-incident impact, functioning as a force multiplier for data exposure. Threat actor methodologies have shifted from opportunistic attacks on individual providers to high-leverage, systemic exploitation of centralized infrastructure. Conclusions - The rise of hacking necessitates a robust re-evaluation of supply-chain cybersecurity protocols and ethical governance to protect patient privacy and national economic stability. Protected Health Information (PHI) Ransomware Hacking Data Breach Figures Figure 1 Introduction The transition of healthcare infrastructure toward centralized, AI-integrated Business Associates (BAs) significantly increases the systemic risk of large-scale data breaches. A Business Associate Agreement (BAA) is the chain of custody for protected health information (PHI), serving as a legal safeguard against the unique threats posed by ransomware. The BAA components include data management, confidentiality safeguards, breach notification obligations, subcontractor compliance, and termination procedures. Regarding ransomware, the agreement provides a high-stakes recovery plan, notification timelines (24–48 hours), and backups [1]. If security is compromised, the legal and financial accountability remains with the party responsible for the data, rather than solely with the healthcare provider [1]. Data sharing PHI, while beneficial for care, raises security and privacy concerns. Ransomware attacks on health information systems are becoming more frequent [2]. Hackers encrypt data and block access to systems until a ransom is paid, and have become a major threat to healthcare operations, disrupting care delivery, and costing the industry approximately $2.4 billion in response efforts alone [3]. A recent report by the HIPAA Journal [4] reported that more than half of all healthcare organizations experienced ransomware attacks in 2024. Of those targeted, 53% paid the ransom, either to prevent the public release of stolen data, regain access to their encrypted files, or both [4]. On average, 15% of companies that paid the ransom never received usable decryption keys, and 3% found that their data had been published or misused despite paying the ransom [4]. Methods To review PHI security concerns, this study focused on large-scale data breaches affecting 500+ records reported to the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024 [5]. Data before 2010 was omitted, as well as data from 2025, due to HIPAA’s 60-day reporting window and reporting lag time. The data indicated 6,374 unique breaches. STATA was used to analyze the frequency, and a log-transformed analysis was conducted to smooth the data distribution and minimize the data. Regression model: Table 1. Data Regression Regression results (1) (2) VARIABLES OLS GLM Log link hp -0.499*** -1.242*** (0.0777) (0.131) hplan -0.676*** -0.617*** (0.101) (0.193) hch -0.606 -2.269*** (0.441) (0.419) Constant 8.047*** 8.983*** (0.375) (0.593) Observations 6,374 6,374 R-squared 0.084 *** p<0.01, ** p<0.05, * p<0.1 Note: Model includes Year, Month, and state fixed effects with robust standard errors. HP = 1 if covered entity is a healthcare provider, 0 otherwise. HPlan = 1 if covered entity is a health plan, 0 otherwise. HCH = 1 if healthcare clearing house, 0 otherwise. There are very few HCH entities in the data. We run both an ordinary least squares (OLS) model and a gamma generalized linear model (GLM) model with a log link to account for the overdispersion of data (higher variance compared to mean, plus data breaching reports for entities with hacking affecting above 500 individuals). Results Analysis revealed approximately 636,560,978 individuals were potentially affected by data breaches [5]. The largest breach involved Change Healthcare, Inc., affecting 192.7 million individuals in February 2024. Attributed to a Ransomware-as-a-Service (RaaS) group, this breach disrupted nearly every facet of the health system by stealing sensitive data (SSNs, records, financial info), causing systemic payment and claims issues, extorting a $22M ransom payment, and ongoing legal issues [6]. BAs (the hubs) are now the primary targets for cyberattacks. This specific cyberattack accounted for a significant portion of the total affected population, pointing out a systemic single point of failure within the healthcare payment and claims infrastructure [7]. As such, this outlier was removed from the dataset. After excluding the Change Healthcare’s attack to minimize variance, a log-transformed analysis was performed due to data overdispersion. Graph 1 demonstrates a sustained positive trend in breach frequency and impact. While hacking incidents are more pronounced over time, breaches are not uniform across all sectors. A comparative analysis between HPs and BAs reveals a strategic shift in the methodology of cybercriminal targets to maximize profits and impact. BAs have higher levels of breaches than HPs, as indicated by Graph 1 (log 9 on average for HPs, and approximately log 10 for BAs). BAs exhibit a higher per-incident impact when hacked (22,495); however, the volume increase is more pronounced for HPs (54,408). Discussion The emergence of RaaS groups has transitioned from localized operational disruptions to systemic economic instability. The findings suggest that the integration of third-party vendors has expanded the attack surface, leading to unprecedented financial liabilities and necessitating a robust re-evaluation of healthcare cybersecurity protocols. The massive scale of the Change Healthcare breach, coupled with the upward trend observed in the log-transformed data, provides sufficient evidence that systemic vulnerabilities in third-party infrastructure represent a statistically higher risk than decentralized provider-level incidents [8]. This breach demonstrates the consequences of centralized digital infrastructure vulnerability of highly connected payment and claims systems. Sensitivity analysis suggests that breach increases continue to trend upward even after excluding this event, suggesting that system risk escalation predates and extends beyond this isolated outlier. Data breaches surged between 2010 and 2024, exhibiting a strategic shift from volume-based opportunistic attacks on individual targets to high-value, systemic exploitation of industry choke points. This evolution is characterized by a tactical pivot toward BAs, which serves as a force multiplier for data exposure by compromising a single centralized hub that manages data for thousands of entities. A similar study urged that “mitigation strategies should include mandatory ransomware fields in OCR reporting to improve surveillance [3].” The emergence of RaaS groups indicates a move toward double extortion, where the theft and threatened PHI exposure are prioritized over system encryption. The data highlights a sophisticated weaponization of infrastructure interdependency where attackers paralyze the national health economy to exert maximum financial pressure, transforming localized cyber incidents into systemic national crises. Declarations Disclosures No funding was provided for this research. Competing Interests: Authors have no financial or non-financial interests that are directly or indirectly related to the work submitted for publication. Data Sharing Statement : Data is Publicly Available References U.S. Department of Health and Human Services. (2013). Business associate contracts. Health Information Privacy. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html Cyber Threat Intelligence Integration Center (2024). Ransomware Attacks Surge in 2023; Attacks on Healthcare Sector Nearly Double. https://www.dni.gov/files/CTIIC/documents/products/Ransomware_Attacks_Surge_in_2023.pdf Jiang, JX, Ross, JS, & Bai, G. (2025). Ransomware Attacks and Data Breaches in US Health Care Systems. JAMA Network Open , 8 (5), e2510180. https://doi.org/10.1001/jamanetworkopen.2025.10180 Alder, S. (2025 Aug 1). More than half of the healthcare orgs attacked with ransomware last year. The HIPAA Journal. https://www.hipaajournal.com/half-healthcare-orgs-successful-ransomware-attack/ Office for Civil Rights (n.d.) Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information . US Department of Health and Human Services (HHS). https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf;jsessionid=AD8F4C3E891DC8AE40909D66AFC9EBDD Cybersecurity & Infrastructure Security Agency. (2024 Feb 27). #StopRansomware: ALPHV Blackcat. America’s Cyber Defense Agency National Coordination for Critical Infrastructure Security and Resilience. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a Olsen, E. (April 8, 2024). Change Healthcare cyber attack lawsuits consolidated in Minnesota. Healthcare Dive . https://www.healthcaredive.com/news/change-healthcare-cyberattack-lawsuit-consolidation/712492/ Abo-Bakr, A, & El-Bakry, HM. (2025). The ripple effect: Analyzing systemic risk in healthcare supply chain cybersecurity. Journal of Cybersecurity and Information Management, 14 (1), 45–62. Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-9151808","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":607919774,"identity":"e13ce861-a564-4df1-8a04-1e604abaebfd","order_by":0,"name":"Tiffany C. Jackman","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAwUlEQVRIiWNgGAWjYFCCAwyMDUCKH8JjJqyBB6ZFsoF4LQwQLQYHiNViz3j44ceZOXZ5xsfPmG5gqLBObCBsyzFjyY3bkovNzuSY3WA4k06MlgNmjA+3MSduOwDUwth2mBgtx78BtdQnbu5/A9TyjygtZ8wYN247nLhBAmRLAzFaDpwplpy57XjijBvPym4kHEs3JqiFfcbxjR97t1Un9vcnb7vxocZalqAWBokDSJwEgspBgJ+wqaNgFIyCUTDSAQACcEZnVZUnQAAAAABJRU5ErkJggg==","orcid":"","institution":"Auburn University at Montgomery","correspondingAuthor":true,"prefix":"","firstName":"Tiffany","middleName":"C.","lastName":"Jackman","suffix":""},{"id":607919781,"identity":"22264773-932a-475f-b800-b125ea0758c2","order_by":1,"name":"Agnitra Roy Choudhury","email":"","orcid":"","institution":"Auburn University at Montgomery","correspondingAuthor":false,"prefix":"","firstName":"Agnitra","middleName":"Roy","lastName":"Choudhury","suffix":""},{"id":607919783,"identity":"9d9262f3-51ac-4141-bf38-ae5240f6a1a0","order_by":2,"name":"Douglas A. Jones","email":"","orcid":"","institution":"Auburn University at Montgomery","correspondingAuthor":false,"prefix":"","firstName":"Douglas","middleName":"A.","lastName":"Jones","suffix":""}],"badges":[],"createdAt":"2026-03-17 18:38:15","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-9151808/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-9151808/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":105149457,"identity":"d3bdc884-f2ff-4142-80f1-aa301f2031aa","added_by":"auto","created_at":"2026-03-22 14:55:31","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":291701,"visible":true,"origin":"","legend":"\u003cp\u003eGraph 1: Individuals’ PHI Affected by Data Breaches\u003c/p\u003e\n\u003cp\u003eNote: This figure illustrates the number of individuals affected by Hacking/IT incidents, categorized by the type of HIPAA-regulated entity. Due to the extreme variance in breach sizes, ranging from 500 to over 10 million records, the data has been log-transformed to stabilize variance and allow for a clear visualization of the underlying trend. While Healthcare Providers (HPs) report a higher total frequency of discrete breach events, Business Associates (BAs) exhibit a higher per-incident impact. The Change Healthcare breach of February 2024 (192.7 million records) has been excluded from this visualization as a statistical outlier to prevent the compression of the remaining data points. Data adapted from the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Breach Portal (2024–2025).\u003c/p\u003e","description":"","filename":"1.png","url":"https://assets-eu.researchsquare.com/files/rs-9151808/v1/e357652adaf0a1a0d7755092.png"},{"id":106679575,"identity":"60420f30-19e2-4f4e-91d7-517fda314395","added_by":"auto","created_at":"2026-04-11 13:55:48","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":555129,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-9151808/v1/b6f5166f-7a7e-4c3f-8f23-1e789eba4369.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Cybersecurity Hacking in HIPAA-Covered Entities: A Longitudinal Trend Analysis","fulltext":[{"header":"Introduction","content":"\u003cp\u003eThe transition of healthcare infrastructure toward centralized, AI-integrated Business Associates (BAs) significantly increases the systemic risk of large-scale data breaches. A Business Associate Agreement (BAA) is the chain of custody for protected health information (PHI), serving as a legal safeguard against the unique threats posed by ransomware. The BAA components include data management, confidentiality safeguards, breach notification obligations, subcontractor compliance, and termination procedures. Regarding ransomware, the agreement provides a high-stakes recovery plan, notification timelines (24\u0026ndash;48 hours), and backups [1]. If security is compromised, the legal and financial accountability remains with the party responsible for the data, rather than solely with the healthcare provider [1].\u003c/p\u003e\n\u003cp\u003eData sharing PHI, while beneficial for care, raises security and privacy concerns. Ransomware attacks on health information systems are becoming more frequent [2]. Hackers encrypt data and block access to systems until a ransom is paid, and have become a major threat to healthcare operations, disrupting care delivery, and costing the industry approximately $2.4 billion in response efforts alone [3].\u003c/p\u003e\n\u003cp\u003eA recent report by the HIPAA Journal [4] reported that more than half of all healthcare organizations experienced ransomware attacks in 2024. Of those targeted, 53% paid the ransom, either to prevent the public release of stolen data, regain access to their encrypted files, or both [4]. On average, 15% of companies that paid the ransom never received usable decryption keys, and 3% found that their data had been published or misused despite paying the ransom [4].\u003c/p\u003e"},{"header":"Methods","content":"\u003cp\u003eTo review PHI security concerns, this study focused on large-scale data breaches affecting 500+ records reported to the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024 [5]. Data before 2010 was omitted, as well as data from 2025, due to HIPAA\u0026rsquo;s 60-day reporting window and reporting lag time. The data indicated 6,374 unique breaches. STATA was used to analyze the frequency, and a log-transformed analysis was conducted to smooth the data distribution and minimize the data.\u003c/p\u003e\n\u003cp\u003eRegression model:\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cimg src=\"https://myfiles.space/user_files/58895_8739fc6c57c1c19a/58895_custom_files/img1774008297.png\" width=\"755\" height=\"48\"\u003e\u003c/p\u003e\n\u003cp\u003eTable 1. Data Regression\u0026nbsp;\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"0\" class=\"fr-table-selection-hover\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 129px;\"\u003e\u003cbr\u003e\u003c/td\u003e\n \u003ctd style=\"width: 63.0682%;\" colspan=\"2\"\u003eRegression results\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e(1)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e(2)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003eVARIABLES\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003eOLS\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003eGLM Log link\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003ehp\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e-0.499***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e-1.242***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e(0.0777)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e(0.131)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003ehplan\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e-0.676***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e-0.617***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e(0.101)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e(0.193)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003ehch\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e-0.606\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e-2.269***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e(0.441)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e(0.419)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003eConstant\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e8.047***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e8.983***\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e(0.375)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e(0.593)\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003eObservations\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e6,374\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e6,374\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 129px;\"\u003e\n \u003cp\u003eR-squared\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 96px;\"\u003e\n \u003cp\u003e0.084\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 124px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e*** p\u0026lt;0.01, ** p\u0026lt;0.05, * p\u0026lt;0.1\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eNote: Model includes Year, Month, and state fixed effects with robust standard errors. HP = 1 if covered entity is a healthcare provider, 0 otherwise. HPlan = 1 if covered entity is a health plan, 0 otherwise. HCH = 1 if healthcare clearing house, 0 otherwise. There are very few HCH entities in the data. We run both an ordinary least squares (OLS) model and a gamma generalized linear model (GLM) model with a log link to account for the overdispersion of data (higher variance compared to mean, plus data breaching reports for entities with hacking affecting above 500 individuals). \u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e"},{"header":"Results","content":"\u003cp\u003eAnalysis revealed approximately 636,560,978 individuals were potentially affected by data breaches [5]. The largest breach involved Change Healthcare, Inc., affecting 192.7 million individuals in February 2024. Attributed to a Ransomware-as-a-Service (RaaS) group, this breach disrupted nearly every facet of the health system by stealing sensitive data (SSNs, records, financial info), causing systemic payment and claims issues, extorting a $22M ransom payment, and ongoing legal issues [6].\u003csup\u003e\u0026nbsp;\u003c/sup\u003eBAs (the hubs) are now the primary targets for cyberattacks. This specific cyberattack accounted for a significant portion of the total affected population, pointing out a systemic single point of failure within the healthcare payment and claims infrastructure [7]. As such, this outlier was removed from the dataset.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eAfter excluding the Change Healthcare\u0026rsquo;s attack to minimize variance, a log-transformed analysis was performed due to data overdispersion. Graph 1 demonstrates a sustained positive trend in breach frequency and impact. While hacking incidents are more pronounced over time, breaches are not uniform across all sectors. A comparative analysis between HPs and BAs reveals a strategic shift in the methodology of cybercriminal targets to maximize profits and impact. BAs have higher levels of breaches than HPs, as indicated by Graph 1 (log 9 on average for HPs, and approximately log 10 for BAs). BAs exhibit a higher per-incident impact when hacked (22,495); however, the volume increase is more pronounced for HPs (54,408).\u003c/p\u003e"},{"header":"Discussion","content":"\u003cp\u003eThe emergence of RaaS groups has transitioned from localized operational disruptions to systemic economic instability. The findings suggest that the integration of third-party vendors has expanded the attack surface, leading to unprecedented financial liabilities and necessitating a robust re-evaluation of healthcare cybersecurity protocols.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThe massive scale of the Change Healthcare breach, coupled with the upward trend observed in the log-transformed data, provides sufficient evidence that systemic vulnerabilities in third-party infrastructure represent a statistically higher risk than decentralized provider-level incidents [8]. This breach demonstrates the consequences of centralized digital infrastructure vulnerability of highly connected payment and claims systems. Sensitivity analysis suggests that breach increases continue to trend upward even after excluding this event, suggesting that system risk escalation predates and extends beyond this isolated outlier.\u003c/p\u003e\n\u003cp\u003eData breaches surged between 2010 and 2024, exhibiting a strategic shift from volume-based opportunistic attacks on individual targets to high-value, systemic exploitation of industry choke points. This evolution is characterized by a tactical pivot toward BAs, which serves as a force multiplier for data exposure by compromising a single centralized hub that manages data for thousands of entities.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eA similar study urged that \u0026ldquo;mitigation strategies should include mandatory ransomware fields in OCR reporting to improve surveillance [3].\u0026rdquo; The emergence of RaaS groups indicates a move toward double extortion, where the theft and threatened PHI exposure are prioritized over system encryption. The data highlights a sophisticated weaponization of infrastructure interdependency where attackers paralyze the national health economy to exert maximum financial pressure, transforming localized cyber incidents into systemic national crises.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eDisclosures\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNo funding was provided for this research. Competing Interests:\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eAuthors have no financial or non-financial interests that are directly or indirectly related to the work submitted for publication.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eData Sharing Statement\u003c/strong\u003e: Data is Publicly Available\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n\u003cli\u003eU.S. Department of Health and Human Services. (2013). Business associate contracts. Health Information Privacy. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html\u003c/li\u003e\n\u003cli\u003eCyber Threat Intelligence Integration Center (2024). \u003cem\u003eRansomware Attacks Surge in 2023; Attacks on Healthcare Sector Nearly Double.\u003c/em\u003e https://www.dni.gov/files/CTIIC/documents/products/Ransomware_Attacks_Surge_in_2023.pdf \u003c/li\u003e\n\u003cli\u003eJiang, JX, Ross, JS, \u0026amp; Bai, G. (2025). Ransomware Attacks and Data Breaches in US Health Care Systems. \u003cem\u003eJAMA Network Open\u003c/em\u003e, \u003cem\u003e8\u003c/em\u003e(5), e2510180. https://doi.org/10.1001/jamanetworkopen.2025.10180\u003c/li\u003e\n\u003cli\u003eAlder, S. (2025 Aug 1). More than half of the healthcare orgs attacked with ransomware last year. \u003cem\u003eThe HIPAA Journal. \u003c/em\u003ehttps://www.hipaajournal.com/half-healthcare-orgs-successful-ransomware-attack/ \u003c/li\u003e\n\u003cli\u003eOffice for Civil Rights (n.d.) \u003cem\u003eBreach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information\u003c/em\u003e. US Department of Health and Human Services (HHS). https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf;jsessionid=AD8F4C3E891DC8AE40909D66AFC9EBDD \u003c/li\u003e\n\u003cli\u003eCybersecurity \u0026amp; Infrastructure Security Agency. (2024 Feb 27). \u003cem\u003e#StopRansomware: ALPHV Blackcat.\u003c/em\u003e America\u0026rsquo;s Cyber Defense Agency National Coordination for Critical Infrastructure Security and Resilience. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a \u003c/li\u003e\n\u003cli\u003eOlsen, E. (April 8, 2024). Change Healthcare cyber attack lawsuits consolidated in Minnesota. \u003cem\u003eHealthcare Dive\u003c/em\u003e. https://www.healthcaredive.com/news/change-healthcare-cyberattack-lawsuit-consolidation/712492/ \u003c/li\u003e\n\u003cli\u003eAbo-Bakr, A, \u0026amp; El-Bakry, HM. (2025). The ripple effect: Analyzing systemic risk in healthcare supply chain cybersecurity. \u003cem\u003eJournal of Cybersecurity and Information Management, 14\u003c/em\u003e(1), 45\u0026ndash;62.\u003c/li\u003e\n\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":true,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Protected Health Information (PHI), Ransomware, Hacking, Data Breach","lastPublishedDoi":"10.21203/rs.3.rs-9151808/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-9151808/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003e\u003cstrong\u003eBackground \u003c/strong\u003e– As healthcare systems increasingly rely on interconnected digital infrastructures and third-party Business Associates (BAs), they have inadvertently expanded the cyber-attack surface. This study analyzed 6,374 large-scale data breaches (500+ records) reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eObjective \u003c/strong\u003e– To evaluate the evolving landscape of large-scale healthcare data breaches by analyzing the frequency, record impact, and longitudinal trends of data breach incidents, specifically comparing the vulnerabilities of healthcare providers versus third-party Business Associates (BAs).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eMethods \u003c/strong\u003e– Using a multiple regression analysis, we compare an ordinary least squares (OLS) model and a generalized linear model (GLM) with a log link and gamma distribution. This study analyzed 6,374 large-scale data breaches (500+ records) reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) between October 2010 and December 2024. We then used STATA to analyze the frequency, and a log-transformed analysis was used to smooth the data distribution and minimize skew of the data.\u003c/p\u003e\n\u003cp\u003eRegression model:\u003c/p\u003e\n\u003cp\u003e𝐿𝑛(𝑏𝑟𝑒𝑎𝑐ℎ)\u003csub\u003e𝑖𝑠𝑚𝑡\u003c/sub\u003e=𝛽\u003csub\u003e0\u003c/sub\u003e+𝛽\u003csub\u003e1\u003c/sub\u003e𝐻𝑃+𝛽\u003csub\u003e2\u003c/sub\u003e𝐻𝑃𝑙𝑎𝑛+𝛽\u003csub\u003e3\u003c/sub\u003e𝐻𝐶𝐻+𝛼\u003csub\u003e𝑠\u003c/sub\u003e+𝛾\u003csub\u003e𝑚\u003c/sub\u003e+𝜇\u003csub\u003e𝑡\u003c/sub\u003e+𝜀\u003csub\u003e𝑖𝑠𝑚𝑡\u003c/sub\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eResults \u003c/strong\u003e– Notably, while healthcare providers report a higher volume of incident growth, Business Associates (BAs) exhibit a higher per-incident impact, functioning as a force multiplier for data exposure. Threat actor methodologies have shifted from opportunistic attacks on individual providers to high-leverage, systemic exploitation of centralized infrastructure.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eConclusions \u003c/strong\u003e- The rise of hacking necessitates a robust re-evaluation of supply-chain cybersecurity protocols and ethical governance to protect patient privacy and national economic stability.\u003c/p\u003e","manuscriptTitle":"Cybersecurity Hacking in HIPAA-Covered Entities: A Longitudinal Trend Analysis","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-03-22 14:55:27","doi":"10.21203/rs.3.rs-9151808/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"1e32c7e6-970d-4e71-a9d1-ecf6bb5e0170","owner":[],"postedDate":"March 22nd, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2026-04-11T13:55:31+00:00","versionOfRecord":[],"versionCreatedAt":"2026-03-22 14:55:27","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-9151808","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-9151808","identity":"rs-9151808","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-24T02:00:01.246996+00:00
License: CC-BY-4.0